tt_printf() function. A local user could abuse this making rxvt
print a special string using that function, for example by using
the -T or -name command-line options.
That string would cause a
stack overflow and contain code which rxvt will execute.
Since rxvt is installed sgid utmp an attacker could use this to gain utmp which would allow them to modify the utmp file.
This has been fixed in version 2.6.2-2.1, and we recommend that you upgrade your rxvt package.
MD5 checksums of the listed files are available in the original advisory.